CVE-2021-29506
Dashboard / Vulnerabilities / CVE-2021-29506
Summary:
Details: GraphHopper is an open-source Java routing engine. In GrassHopper from version 2.0 and before version 2.4, there is a regular expression injection vulnerability that may lead to Denial of Service. This has been patched in 2.4 and 3.0 See this pull request for the fix: https://github.com/graphhopper/graphhopper/pull/2304
References: https://github.com/graphhopper/graphhopper/security/advisories/GHSA-hf44-3mx6-vhhw, https://github.com/graphhopper/graphhopper/commit/eb189be1fa7443ebf4ae881e737a18f818c95f41, https://github.com/graphhopper/graphhopper/pull/2304
Affected packages
Package
Name:
Purl:
Affected ranges
Type: GIT
Events:
Introduced- 7e3a98bd316745a7cc48ba78958624b9544e4d61
Affected versions
2.3
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
